troubleshooting Question

Account getting locked in Microsoft CAS server, exchange 2013

Avatar of Imran Yousaf
Imran Yousaf asked on
ExchangeEmail Servers
10 Comments4 Solutions2420 ViewsLast Modified:
One account in our domain is getting locked again and again , from active directory  i used three tool to find out the source and all tools show that the workstation is our CAS server .i shut down the client machine and account got locked within half an hour after shutting down. the tool i used are "Account lockout status" , "Netwrix Account lockout Examiner" and "Manage engine ADAudit Plus" also event viewer on AD  is showing the log as below

Kerberos pre-authentication failed.
Account Information:
      Security ID:            MIC\ofekry
      Account Name:            ofekry

Service Information:
      Service Name:            krbtgt/mic

Network Information:
      Client Address:            ::ffff:--.--.--.--    (CAS server Address)
      Client Port:            60818

Additional Information:
      Ticket Options:            0x40810010
      Failure Code:            0x18
      Pre-Authentication Type:      2

Certificate Information:
      Certificate Issuer Name:            
      Certificate Serial Number:       
      Certificate Thumbprint:            

Certificate information is only provided if a certificate was used for pre-authentication.
Pre-authentication types, ticket options and failure codes are defined in RFC 4120.
if the ticket was malformed or damaged during transit and could not be decrypted, then many fields in this event might not be present.

I also logged in to the CAS server and executed the command in exchange shell and below is the result

[PS] C:\Windows\system32>Get-ActiveSyncDeviceStatistics -Mailbox ofekry
Creating a new session for implicit remoting of "Get-ActiveSyncDeviceStatistics" command...
WARNING: The Get-ActiveSyncDeviceStatistics cmdlet will be removed in a future version of Exchange. Use the
Get-MobileDeviceStatistics cmdlet instead. If you have any scripts that use the Get-ActiveSyncDeviceStatistics cmdlet,
update them to use the Get-MobileDeviceStatistics cmdlet.  For more information, see
http://go.microsoft.com/fwlink/p/?LinkId=254711.


RunspaceId                    : 4a009f23-d25f-4e9c-b867-b8cd83259dbd
DeviceActiveSyncVersion       : 14.1
FirstSyncTime                 : 3/24/2015 11:52:50 AM
LastPolicyUpdateTime          : 11/2/2015 1:58:06 PM
LastSyncAttemptTime           : 9/18/2016 7:09:18 AM
LastSuccessSync               : 9/18/2016 7:09:18 AM
DeviceType                    : iPhone
DeviceID                      : A0BEPH6S8L3IB9LNNUJSK9EBE8
DeviceUserAgent               : Apple-iPhone7C2/1401.403
DeviceWipeSentTime            :
DeviceWipeRequestTime         :
DeviceWipeAckTime             :
LastPingHeartbeat             : 900
RecoveryPassword              : ********
DeviceModel                   : iPhone7C2
DeviceImei                    :
DeviceFriendlyName            : iPhone 6
DeviceOS                      : iOS 10.0.1 14A403
DeviceOSLanguage              : en-KW
DevicePhoneNumber             :
MailboxLogReport              :
DeviceEnableOutboundSMS       : False
DeviceMobileOperator          :
Identity                      : MIC.COM.KW/MICOU/UserAccounts/Standard/Finance/Omar
                                Fekry/ExchangeActiveSyncDevices/iPhone§A0BEPH6S8L3IB9LNNUJSK9EBE8
Guid                          : ce703a7d-dc6c-4d45-be23-49b65e59da7a
IsRemoteWipeSupported         : True
Status                        : DeviceOk
StatusNote                    :
DeviceAccessState             : Allowed
DeviceAccessStateReason       : Global
DeviceAccessControlRule       :
DevicePolicyApplied           : Default
DevicePolicyApplicationStatus : AppliedInFull
LastDeviceWipeRequestor       :
NumberOfFoldersSynced         : 8
SyncStateUpgradeTime          :
ClientType                    : EAS
IsValid                       : True
ObjectState                   : Unchanged

RunspaceId                    : 4a009f23-d25f-4e9c-b867-b8cd83259dbd
DeviceActiveSyncVersion       : 14.1
FirstSyncTime                 : 12/16/2014 1:01:09 PM
LastPolicyUpdateTime          : 12/17/2014 3:31:21 AM
LastSyncAttemptTime           : 3/24/2015 7:36:10 PM
LastSuccessSync               : 3/24/2015 7:36:10 PM
DeviceType                    : SAMSUNGGTI9500
DeviceID                      : SEC12B0DAB3C46E7
DeviceUserAgent               : SAMSUNG-GT-I9500/101.40402
DeviceWipeSentTime            :
DeviceWipeRequestTime         :
DeviceWipeAckTime             :
LastPingHeartbeat             : 470
RecoveryPassword              : ********
DeviceModel                   : GT-I9500
DeviceImei                    : 357138055578543
DeviceFriendlyName            : ja3gxx
DeviceOS                      : Android
DeviceOSLanguage              : English
DevicePhoneNumber             :
MailboxLogReport              :
DeviceEnableOutboundSMS       : False
DeviceMobileOperator          :
Identity                      : MIC.COM.KW/MICOU/UserAccounts/Standard/Finance/Omar
                                Fekry/ExchangeActiveSyncDevices/SAMSUNGGTI9500§SEC12B0DAB3C46E7
Guid                          : f6647896-964a-4bfe-8804-7f84a1832ca3
IsRemoteWipeSupported         : True
Status                        : DeviceOk
StatusNote                    :
DeviceAccessState             : Allowed
DeviceAccessStateReason       : Global
DeviceAccessControlRule       :
DevicePolicyApplied           : Default
DevicePolicyApplicationStatus : AppliedInFull
LastDeviceWipeRequestor       :
NumberOfFoldersSynced         : 7
SyncStateUpgradeTime          : 12/16/2014 1:17:20 PM
ClientType                    : EAS
IsValid                       : True
ObjectState                   : Unchanged


As you can see that the last successful sync was on 18th of last month because i removed the account from his mobile . so the mobile is not the source

So basically i have 2 questions
first question :  Is there a way to find out what is trying to authenticate from exchange, i mean is it a mobile device or a machine with  ms outlook or web access or any other device that require authentication . in short i want to know the type of authentication if possible like type 1 = outlook , type 2 = mobile device , type 3 = webaccess etc etc.
second question : how can i find out the source address of device or machine who is trying to get authenticated from exchange

also note that as i mention above ,the source machine of locked account is Exchange server and not the client machine also i shutdown the client machine and still the account got locked which means that client machine is not initiating authentication request .

Please help me in diagnosing the said account lockout issue.

Regards

Imran.
SOLUTION
Scott C
Senior Engineer

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 4 Answers and 10 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 4 Answers and 10 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros